Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 56 guests and 1 member online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow OSCP - Offensive Security Certified Professionalarrow interception proxy allow (eg. free version burp or paros) in exam?
EH-Net
May 19, 2013, 08:12:43 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Poll
Question: interception proxy allow (eg. free version burp or paros) in exam?
yes - 3 (100%)
no - 0 (0%)
Total Voters: 3

Pages: [1]   Go Down
  Print  
Author Topic: interception proxy allow (eg. free version burp or paros) in exam?  (Read 4564 times)
0 Members and 1 Guest are viewing this topic.
stock99
Newbie
*
Offline Offline

Posts: 2


View Profile
« on: February 25, 2012, 12:36:39 AM »

HI,

I understand that the oscp is designed to make us do the pentest without automated tool.  But is interception proxy (free version burp) or paros allow to be used in the challenges exam?  Or are we expected to manually test web application vulnerability via browser?  


Also, another question for the exam, do we get a similar set up like in the lap (where we get access to an xp machine) or more like actual blackbox pentest that we start with an ip address?
Logged
MaXe
Hero Member
*****
Offline Offline

Posts: 669


I've just upgraded myself to a cyborg muahahaa!!1


View Profile WWW
« Reply #1 on: February 25, 2012, 07:16:29 AM »

I don't see why your poll has the same question twice (would've been better with a yes or no poll), but yes, you can use burp or paros, as they won't automatically give you root like Metasploit with e.g., Armitage can do  Smiley

Sometimes, you have to use an intercepting proxy to perform specific types of web application attacks, and the spider function is just to help you find available files to perhaps play with.
(You still have to use other tools or do it manually afterward, and don't rely 100% on the tools in case they fail, because they can do that a lot when it comes to filters and e.g., unusual SQL Injection.)

Tamper Data in FireFox, is much like an intercepting proxy too except that it doesn't have a spider function as far as I know, but you can definitely use that.

An intercepting proxy is not really cheating, as it allows you to intercept and modify requests, before they're sent, which is useful for e.g., modifying headers. If you didn't use an intercepting proxy of some sort, you would have to e.g., capture the traffic in Wireshark and write scripts in perhaps Python with custom headers, in case a header was an injection point.

About the actual exam, it'll most likely be like a blackbox pentest just as described on the website. You will get more info about this, when you do the actual exam.
« Last Edit: February 25, 2012, 07:18:08 AM by MaXe » Logged

I'm an InterN0T'er
stock99
Newbie
*
Offline Offline

Posts: 2


View Profile
« Reply #2 on: February 25, 2012, 11:06:26 PM »

sorry for the poll, I must have clicked on the wrong option when posting the thread. So i simply put something there in order to post it.  Any way I can remove it?

Thanks for the thorough response.  I guess I can assume the bottom line for the exam preparation is to focus to own the target within the given constraint(things like using metasploit once , ips in place and absence of access to certain tools, etc).  

By the way, I am just wondering, if there is a value to sit for the exam to see those constraints used in exam? I am not aim to pass it the first time but hopefully pass it sometime this year or next year.  For me I need to get this certificate to get my pentest career started(as per my last interviewer).
« Last Edit: February 25, 2012, 11:11:46 PM by stock99 » Logged
MaXe
Hero Member
*****
Offline Offline

Posts: 669


I've just upgraded myself to a cyborg muahahaa!!1


View Profile WWW
« Reply #3 on: February 26, 2012, 09:39:03 AM »

Yes there's a huge value in doing the exam, whether you pass it or not. If you don't pass, you will (hopefully) know where to improve (as I did with OSCE), and become even better. You will also learn how to work under stress during a pentest, and to manage your time the best you're able to.  Smiley
Logged

I'm an InterN0T'er
cd1zz
Hero Member
*****
Offline Offline

Posts: 561


View Profile WWW
« Reply #4 on: February 26, 2012, 09:52:19 AM »

+ 1 to your last interviewer for recommending OSCP!

Don't over think the OSCP, just dive in and see how it goes. There are too many things going on to try and pin it down for the exam. It's more about the experience, and if you enjoy the experience, you'll likely do fine on the exam.
Logged

j0rDy
Hero Member
*****
Offline Offline

Posts: 590


View Profile
« Reply #5 on: March 01, 2012, 02:26:51 AM »

yes, it is allowed...the only restrictions are on metasploit and other (automated) pwntools like canvas...good luck!
Logged

ISC2 Associate, CEH, ECSA, OSCP, OSWP

earning my stripes appears to be a road i must travel alone...with a little help of EH.net
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.053 seconds with 25 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.